DON'T WANT TO MISS A THING?

Certification Exam Passing Tips

Latest exam news and discount info

Curated and up-to-date by our experts

Yes, send me the newsletter

Updated Microsoft MD-102 Exam Questions for Effective Preparation

The SPOTO Microsoft MD-102 Exam Questions offer a comprehensive set of exam questions and answers, test questions, mock exams, and study materials tailored for candidates preparing for the Microsoft 365 Certified: Endpoint Administrator Associate certification. These valuable exam resources cover all the essential topics required to deploy, configure, protect, manage, and monitor devices and client applications in a Microsoft 365 environment. With SPOTO's MD-102 exam preparation resources, you can assess your knowledge level, identify areas that require further study, and practice with realistic mock exams that simulate the actual exam environment. These meticulously crafted exam questions and answers are developed by subject matter experts to mirror the complexity and format of the real MD-102 exam, boosting your confidence and increasing your chances of passing successfully on your first attempt. By leveraging these exam resources, you can ensure a thorough understanding of the subject matter and enhance your readiness for the Microsoft 365 Certified: Endpoint Administrator Associate certification.
Take other online exams

Question #1
You have a Microsoft Intune subscription.You have devices enrolled in intune as shown in the following table. An app named App1 is installed on each device.What is the minimum number of app configuration policies required to manage Appl?
A.
B.
C.
D.
E.
View answer
Correct Answer: B

View The Updated MD-102 Exam Questions

SPOTO Provides 100% Real MD-102 Exam Questions for You to Pass Your MD-102 Exam!

Question #2
RAG DROPYou have a Microsoft 365 subscription that contains two users named User1 and User2.You need to ensure that the users can perform the following tasks:-User1 must be able to create groups and manage users.-User2 must be able to reset passwords for nonadministrative users.The solution must use the principle of least privilege.Which role should you assign to each user? To answer, drag the appropriate roles to the correct users. Each role may be used once, more than once, or not at all. You may need to
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #3
You have a Microsoft 365 subscription that contains 1,000 Windows 11 devices enrolled in Microsoft Intune.You plan to use Intune to deploy an application named App1 that contains multiple installation files.What should you do first?
A. repare the contents of App1 by using the Microsoft Win32 Content Prep Tool
B. reate an Android application package (APK)
C. pload the contents of App1 to Intune
D. nstall the Microsoft Deployment Toolkit (MDT)
View answer
Correct Answer: A
Question #4
You have a Microsoft 365 subscription.You have 10 computers that run Windows 10 and are enrolled in mobile device management (MDM). You need to deploy the Microsoft 36S Apps for enterprise suite to all the computers. What should you do?
A. rom the Microsoft Intune admin center, create a Windows 10 device profile
B. rom Azure AD, add an app registration
C. rom Azure AD
D. rom the Microsoft Intune admin center, add an app
View answer
Correct Answer: D
Question #5
You have a Microsoft 365 subscription that contains a user named User1 and uses Microsoft Intune Suite.You use Microsoft Intune to manage devices that run Windows 11.User provides remote support for 75 devices in the marketing department.You need to add User1 to the Remote Desktop Users group on each marketing department device.What should you configure?
A. n app configuration policy
B. device compliance policy
C. n account protection policy
D. device configuration profile
View answer
Correct Answer: C
Question #6
HOTSPOT (Drag and Drop is not supported)You create a Windows Autopilot deployment profile.You need to configure the profile settings to meet the following requirements:-Automatically enroll new devices and provision system apps without requiring end-user authentication-Include the hardware serial number in the computer name.Which two settings should you configure? To answer, select the appropriate settings in the answer area.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #7
You have an Azure AD tenant that contains the devices shown in the following table.Which devices can be activated by using subscription activation?
A. evice1 only
B. evice1 and Device2 only
C. evice1 and Device3 only
D. evice1, Device2, Device3, and Device4
View answer
Correct Answer: C
Question #8
Your network contains an Active Directory domain. The domain contains a user named Admin1. All computers run Windows 10.You enable Windows PowerShell remoting on the computers.You need to ensure that Admin1 can establish remote PowerShell connections to the computers. The solution must use the principle of least privilege.To which group should you add Admin1?
A. ccess Control Assistance Operators
B. emote Desktop Users
C. ower Users
D. emote Management Users
View answer
Correct Answer: D
Question #9
HOTSPOT (Drag and Drop is not supported)You have 100 computers that run Windows 10. You have no servers. All the computers are joined to Microsoft Azure Active Directory (Azure AD).The computers have different update settings, and some computers are configured for manual updates.You need to configure Windows Update. The solution must meet the following requirements: -The configuration must be managed from a central location.-Internet traffic must be minimized.-Costs must be minimized.How should you configur
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #10
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage devices. You use Windows Autopilot to deploy Windows 11 to devices.A support engineer reports that when a deployment fails, they cannot collect deployment logs from failed device.You need to ensure that when a deployment fails, the deployment logs can be collected. What should you configure?
A. he automatic enrollment settings
B. he Windows Autopilot deployment profile
C. he enrollment status page (ESP) profile
D. he device configuration profile
View answer
Correct Answer: C
Question #11
HOTSPOT (Drag and Drop is not supported)You have a Microsoft 365 tenant that uses Microsoft Intune to manage personal and corporate devices. The tenant contains Windows 10 devices as shown in the following exhibit.How will Intune classify each device after the devices are enrolled in Intune automatically? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #12
You have a Microsoft 365 subscription that includes Microsoft Intune.You have an update ring named UpdateRing1 that contains the following settings:-Automatic update behavior: Auto install and restart at a scheduled time-Automatic behavior frequency: First week of the month-Scheduled install day: Tuesday-Scheduled install time: 3 AMFrom the Microsoft Intune admin center, you select Uninstall for the feature updates of UpdateRing1.When will devices start to remove the feature updates?
A. rom Group Policy Management Editor, configure the Computer Configuration settings in the Default Domain Policy
B. rom the Microsoft Intune admin center, create a custom device profile
C. rom the Microsoft Intune admin center, create an Administrative Templates device profile
D. rom Group Policy Management Editor, configure the User Configuration settings in the Default Domain Policy
View answer
Correct Answer: B
Question #13
You use the Microsoft Deployment Toolkit (MDT) to manage Windows 11 deployments.From Deployment Workbench, you modify the WinPE settings and add PowerShell support.You need to generate a new set of WinPE boot image files that contain the updated settings.What should you do?
A. rom the Deployment Shares node, update the deployment share
B. rom the Advanced Configuration node, create new media
C. rom the Packages node, import a new operating system package
D. rom the Operating Systems node, import a new operating system
View answer
Correct Answer: A
Question #14
Case study -Overview -Contoso, Ltd. is a consulting company that has a main office in Montreal and two branch offices in Seattle and New York.Contoso has the users and computers shown in the following table.The company has IT, human resources (HR), legal (LEG), marketing (MKG), and finance (FIN) departments.Contoso recently purchased a Microsoft 365 subscription.The company is opening a new branch office in Phoenix. Most of the users in the Phoenix office will work from home.Existing Environment -The networ
A. Generalize the computers and configure the Device settings from the Microsoft Entra admin center
B. Extract the serial number of each computer to an XML file and upload the file from the Microsoft Intune admin center
C. Extract the hardware ID information of each computer to a CSV file and upload the file from the Microsoft Intune admin center
D. Generalize the computers and configure the Mobility (MDM and MAM) settings from the Microsoft Entra admin center
E. Extract the serial number information of each computer to a CSV file and upload the file from the Microsoft Intune admin center
View answer
Correct Answer: C
Question #15
Your company has 200 computers that run Windows 10. The computers are managed by using Microsoft Intune.Currently, Windows updates are downloaded without using Delivery Optimization.You need to configure the computers to use Delivery Optimization.What should you create in Intune?
A. device compliance policy
B. Windows 10 update ring
C. device configuration profile
D. n app protection policy
View answer
Correct Answer: C
Question #16
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage devices.You have a Windows 11 device named Device1 that is enrolled in Intune. Device1 has been offline for 30 days.You need to remove Device1 from Intune immediately. The solution must ensure that if the device checks in again, any apps and data provisioned by Intune are removed. User-installed apps, personal data, and OEM-installed apps must be retained.What should you use?
A. Delete action
B. Retire action
C. Fresh Start action
D. n Autopilot Reset action
View answer
Correct Answer: B
Question #17
Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you configure the Windows Hello for
A. es
B. o
View answer
Correct Answer: A
Question #18
DRAG DROP (Drag and Drop is not supported)You have a Microsoft Deployment Toolkit (MDT) server named MDT1.When computers start from the LiteTouchPE_x64.lso image and connect to MDT1. the welcome screen appears as shown in the following exhibit. You need to prevent the welcome screen from appearing when the computers connect to MDT1. Which three actions should you perform in sequence? To answer move the appropriate actions from
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #19
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Microsoft Intune to manage devices.You plan to deploy two apps named App1 and App2 to all Windows devices. Appl must be installed before App2.From the Intune admin center, you create and deploy two Windows app (Win32) apps. You need to ensure that App1 is installed before App2 on every device.What should you configure?
A. he App1 deployment configurations
B. dynamic device group
C. detection rule
D. he App2 deployment configurations
View answer
Correct Answer: D
Question #20
You install a feature update on a computer that runs Windows 10.How many days do you have to roll back the update?
A.
B. 0
C. 4
D. 0
View answer
Correct Answer: B
Question #21
You have a computer named Computer1 that runs Windows 11.A user named User1 plans to use Remote Desktop to connect to Computer1.You need to ensure that the device of User1 is authenticated before the Remote Desktop connection is established and the sign in page appears.What should you do on Computer1?
A. urn on Reputation-based protection
B. nable Network Level Authentication (NLA)
C. urn on Network Discovery
D. onfigure the Remote Desktop Configuration service
View answer
Correct Answer: B
Question #22
You have an Azure Active Directory (Azure AD) tenant named contoso.com that contains the devices shown in the following table.Contoso.com contains the Azure Active Directory groups shown in the following table.You add a Windows Autopilot deployment profile. The profile is configured as shown in the following exhibit. For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #23
You have computers that run Windows 11 Pro. The computers are joined to Azure AD and enrolled in Microsoft Intune.You need to upgrade the computers to Windows 11 Enterprise.What should you configure in Intune?
A. device compliance policy
B. device cleanup rule
C. device enrollment policy
D. device configuration profile
View answer
Correct Answer: D
Question #24
DRAG DROP (Drag and Drop is not supported)You have a Microsoft 365 subscription that contains the devices shown in the following table.You need to ensure that only devices running trusted firmware or operating system build can access network resources.Which compliance policy setting should you configure for each device? To answer, drag the appropriate settings to the correct devices. Each setting may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to v
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #25
Your company uses Microsoft Intune.More than 500 Android and iOS devices are enrolled in the Intune tenant.You plan to deploy new Intune policies. Different policies will apply depending on the version of Android or iOS installed on the device.You need to ensure that the policies can target the devices based on their version of Android or iOS.What should you configure first?
A. roups that have dynamic membership rules in Azure AD
B. evice categories in Intune
C. orporate device identifiers in Intune
D. evice settings in Azure AD
View answer
Correct Answer: A
Question #26
HOTSPOT (Drag and Drop is not supported)You have groups that use the Dynamic Device membership type as shown in the following table.You are deploying Microsoft 365 apps.You have devices enrolled in Microsoft Intune as shown in the following table.In the Microsoft Intune admin center, you create a Microsoft 365 Apps app as shown in the exhibit. (Click the Exhibit tab.)For each of the following statements, select Yes if the statement is true. Otherwise, select No.NOTE: Each correct selection is worth one poin
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #27
You have a Microsoft 365 E5 subscription that contains 500 macOS devices enrolled in Microsoft Intune.You need to ensure that you can apply Microsoft Defender for Endpoint antivirus policies to the macOS devices. The solution must minimize administrative effort.What should you do?
A. nboard the macOS devices to the Microsoft Purview compliance portal
B. rom the Microsoft Intune admin center, create a security baseline
C. nstall Defender for Endpoint on the macOS devices
D. rom the Microsoft Intune admin center, create a configuration profile
View answer
Correct Answer: D
Question #28
HOTSPOT (Drag and Drop is not supported)Your network contains an on-premises Active Directory Domain Services (AD DS) domain that syncs with an Azure AD tenant. The tenant contains the users shown in the following table.You assign Windows 10/11 Enterprise E5 licenses to Group1 and User2.You deploy the devices shown in the following table.For each of the following statements, select Yes if the statement is true. Otherwise, select No.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #29
HOTSPOT (Drag and Drop is not supported)To which devices do Policy1 and Policy2 apply? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #30
You are replacing 100 company-owned Windows devices.You need to use the Microsoft Deployment Toolkit (MDT) to securely wipe and decommission the devices. The solution must meet the following requirements:? Back up the user state.? Minimize administrative effort.Which task sequence template should you use?
A. Standard Client Task Sequence
B. Standard Client Replace Task Sequence
C. Litetouch OEM Task Sequence
D. Sysprep and Capture
View answer
Correct Answer: B
Question #31
You have a Microsoft 365 subscription that contains 500 Android Enterprise devices.All the devices are enrolled in Microsoft Intune.You need to deliver bookmarks to the Chrome browser on the devices.What should you create?
A. compliance policy
B. configuration profile
C. n app protection policy
D. n app configuration policy
View answer
Correct Answer: D
Question #32
You have a Microsoft 365 E5 subscription that contains 100 iOS devices enrolled in Microsoft Intune. You need to deploy a custom line-of-business (LOB) app to the devices by using Intune.Which extension should you select for the app package file?
A.
B.
C.
D.
View answer
Correct Answer: B
Question #33
DRAG DROP (Drag and Drop is not supported)You have 500 Windows 10 devices enrolled in Microsoft Intune.You plan to use Exploit protection in Microsoft Intune to enable the following system settings on the devices:-Data Execution Prevention (DEP)-Force randomization for images (Mandatory ASLR)You need to configure a Windows 10 device that will be used to create a template file.Which protection areas on the device should you configure in the Windows Security app before you create the template file? To answer,
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #34
You use Microsoft Intune and Intune Data Warehouse.You need to create a device inventory report that includes the data stored in the data warehouse. What should you use to create the report?
A. he Azure portal app
B. ndpoint analytics
C. he Company Portal app
D. icrosoft Power Bl
View answer
Correct Answer: D
Question #35
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.You use Microsoft Intune to manage devices.You need to ensure that the startup performance of managed Windows 11 devices is captured and available for review in the Intune admin center.What should you configure?
A. he Azure Monitor agent
B. device compliance policy
C. Conditional Access policy
D. n Intune data collection policy
View answer
Correct Answer: D
Question #36
DRAG DROP (Drag and Drop is not supported)You have a Microsoft 365 subscription. The subscription contains computers that run Windows 11 and are enrolled in Microsoft Intune. You need to create a compliance policy that meets the following requirements:Requires BitLocker Drive Encryption (BitLocker) on each device Requires a minimum operating system versionWhich setting of the compliance policy should you configure for each requirement? To answer, drag the appropriate settings to the correct requirements. Ea
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #37
You use a Microsoft Intune subscription to manage iOS devices.You configure a device compliance policy that blocks jailbroken iOS devices.You need to enable Enhanced jailbreak detection.What should you configure?
A. he Compliance policy settings
B. he device compliance policy
C. network location
D. configuration profile
View answer
Correct Answer: B
Question #38
DRAG DROP (Drag and Drop is not supported)You have a Microsoft Intune subscription that is configured to use a PFX certificate connector to an on-premises Enterprise certification authority (CA).You need to use Intune to configure autoenrollment for Android devices by using public key pair (PKCS) certificates.Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #39
DRAG DROP (Drag and Drop is not supported)Your company has a computer named Computer1 that runs Windows 10.Computer1 was used by a user who left the company.You plan to repurpose Computer1 and assign the computer to a new user.You need to redeploy Computer1 by using Windows Autopilot.Which three actions should you perform in sequence? To answer, move the appropriate actions from the list of actions to the answer area and arrange them in the correct order.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #40
You have devices enrolled in Microsoft Intune as shown in the following table.On which devices can you apply app configuration policies?
A. evice2 only
B. evice1 and Device2 only
C. evice3 and Device4 only
D. evice2, Device3, and Device4 only
E. evice1, Device2, Device B, and Device4
View answer
Correct Answer: D
Question #41
Your company has an Azure AD tenant named contoso.com that contains several Windows 10 devices.When you join new Windows 10 devices to contoso.com, users are prompted to set up a four-digit pin.You need to ensure that the users are prompted to set up a six-digit pin when they join the Windows 10 devices to contoso.com.Solution: From the Microsoft Entra admin center, you configure automatic mobile device management (MDM) enrollment. From the Microsoft Intune admin center, you create and assign a device restr
A. es
B. o
View answer
Correct Answer: B
Question #42
Your network contains an Active Directory domain named contoso.com. The domain contains two computers named Computer1 and Computer2 that run Windows 10.On Computer1, you need to run the Invoke-Command cmdlet to execute several PowerShell commands on Computer2.What should you do first?
A. n Computer2, run the Enable-PSRemoting cmdlet
B. n Computer2, add Computer1 to the Remote Management Users group
C. rom Active Directory, configure the Trusted for Delegation setting for the computer account of Computer2
D. n Computer1, run the New-PSSession cmdlet
View answer
Correct Answer: A
Question #43
You have an on-premises server named Server! that hosts a Microsoft Deployment Toolkit (MDT) deployment share named MDT1. You need to ensure that MDT1 supports multicast deployments. What should you install on Server1?
A. ultipath I/O (MPIO)
B. ultipoint Connector
C. indows Deployment Services (WDS)
D. indows Server Update Services (WSUS)
View answer
Correct Answer: C
Question #44
HOTSPOT (Drag and Drop is not supported)You have a Microsoft 365 subscription.You use Microsoft Intune Suite to manage devices.You have the iOS app protection policy shown in the following exhibit. Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic. NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #45
You have a Microsoft 365 E5 subscription that contains 1,000 Windows 11 devices. All the devices are enrolled in Microsoft Intune.You plan to integrate Intune with Microsoft Defender for Endpoint.You need to establish a service-to-service connection between Intune and Defender for Endpoint.Which settings should you configure in the Microsoft Intune admin center?
A. remium add-ons
B. onnectors and tokens
C. enant enrollment
D. icrosoft Tunnel Gateway
View answer
Correct Answer: C
Question #46
You have computer that run Windows 10 and connect to an Azure Log Analytics workspace. The workspace is configured to collect all available events from Windows event logs.The computers have the logged events shown in the following table. Which events are collected in the Log Analytics workspace?
A. only
B. and 3 only
C. and 3 only
D. , 2, and 4 on
E. , 2, 3, and 4
View answer
Correct Answer: D
Question #47
You have a Microsoft Deployment Toolkit (MDT) deployment share.From the Deployment Workbench, you open the New Task Sequence Wizard and select the Standard Client Upgrade Task Sequence task sequence template.You discover that there are no operating system images listed on the Select OS page as shown in the following exhibit.You need to be able to select an operating system image to perform a Windows 11 in-place upgrade.What should you do?
A. nable monitoring for the deployment share
B. mport a full set of source files
C. mport a custom image file
D. un the Update Deployment Share Wizard
View answer
Correct Answer: B
Question #48
HOTSPOT (Drag and Drop is not supported)Your network contains an Active Directory domain. The domain contains 1.000 computers that run Windows 11.You need to configure the Remote Desktop settings of all the computers. The solution must meet the following requirements:-Prevent the sharing of clipboard contents.-Ensure that users authenticate by using Network Level Authentication (NLA).Which two nodes of the Group Policy Management Editor should you use? To answer, select the appropriate nodes in the answer a
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #49
HOTSPOT (Drag and Drop is not supported)You have a Microsoft Intune subscription that has the following device compliance policy settings:-Mark devices with no compliance policy assigned as: Compliant-Compliance status validity period (days): 14On January1, you enroll Windows 10 devices in Intune as shown in the following table.On January 4, you create the following two device compliance policies:-Name: Policy1-Platform: Windows 10 and later-Require BitLocker: Require-Mark device noncompliant: 5 days after
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #50
Case study -Overview -ADatum Corporation is a consulting company that has a main office in Montreal and branch offices in Seattle and New York.ADatum has a Microsoft 365 E5 subscription.Environment -Network Environment -The network contains an on-premises Active Directory domain named adatum.com. The domain contains the servers shown in the following table.ADatum has a hybrid Azure AD tenant named adatum.com.Users and Groups -The adatum.com tenant contains the users shown in the following table.All users ar
A. evice2 only
B. evice3 only
C. evice1, Device2, and Device5 only
D. evice1, Device2, Device3, and Device4 only
View answer
Correct Answer: C
Question #51
You use the Microsoft Deployment Toolkit (MDT) to deploy Windows 11.You create a new task sequence by using the Standard Client Task Sequence template to deploy Windows 11 Enterprise to new computers. The computers have a single hard disk.You need to modify the task sequence to create a system volume and a data volume.Which phase should you modify in the task sequence?
A. nitialization
B. tate Restore
C. reinstall
D. ostinstall
View answer
Correct Answer: C
Question #52
HOTSPOT (Drag and Drop is not supported)In Microsoft Intune, you have the device compliance policies shown in the following table.The Intune compliance policy settings are configured as shown in the following exhibit.On June 1, you enroll Windows 10 devices in Intune as shown in the following table.For each of the following statements, select Yes if the statement is true. Otherwise, select No.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #53
HOTSPOT (Drag and Drop is not supported)You have an Azure AD tenant named contoso.com that contains a user named User1. User1 has a user principal name (UPN) of user1@contoso.com.You join a Windows 11 device named Client1 to contoso.com.You need to add User1 to the local Administrators group of Client1.How should you complete the command? To answer, select the appropriate options in the answer area.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #54
You have 100 computers that run Windows 10 and connect to an Azure Log Analytics workspace. Which three types of data can you collect from the computers by using Log Analytics? Each correct answer a complete solution.NOTE: Each correct selection is worth one point.
A. n attack surface reduction (ASR) policy
B. security baseline
C. n endpoint detection and response (EDR) policy
D. n account protection policy
E. n antivirus policy
View answer
Correct Answer: CDE
Question #55
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.You use Microsoft Intune to manage devices.You have the devices shown in the following table.Which devices can be changed to Windows 11 Enterprise by using subscription activation?
A. evice3 only
B. evice2 and Device3 only
C. evice1 and Device2 only
D. evice1, Device2, and Device3
View answer
Correct Answer: B
Question #56
For each of the following statements, select Yes if the statement is true. Otherwise, select No.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #57
You have a Microsoft 365 subscription.You need to provide a user the ability Security defaults and create Conditional Access policies. The solution must use the principle of least privilege.Which role should you assign to the user?
A. lobal Administrator
B. onditional Access Administrator
C. ecurity Administrator
D. ntune Administrator
View answer
Correct Answer: B
Question #58
Which devices are registered by using the Windows Autopilot deployment service?
A. evice1 only
B. evice3 only
C. evice1 and Device3 only
D. evice1, Device2, and Device3
View answer
Correct Answer: A
Question #59
HOTSPOT (Drag and Drop is not supported)You have an Azure AD tenant named contoso.com that contains the users shown in the following table.You have a computer named Computer1 that runs Windows 10. Computer1 is in a workgroup and has the local users shown in the following table. UserA joins Computer1 to Azure AD by using user1@contoso.com.For each of the following statements, select Yes if the statement is true. Otherwise, select No. NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #60
DRAG DROP (Drag and Drop is not supported)You have a Microsoft 365 subscription that contains devices enrolled in Microsoft Intune.You need to create Endpoint security policies to enforce the following requirements:-Computers that run macOS must have FileVault enabled.-Computers that run Windows 10 must have Microsoft Defender Credential Guard enabled.-Computers that run Windows 10 must have Microsoft Defender Application Control enabled.Which Endpoint security feature should you use for each requirement? T
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #61
You have a Microsoft Intune subscription.You are creating a Windows Autopilot deployment profile named Profile1 as shown in the following exhibit.Use the drop-down menus to select the answer choice that completes each statement based on the information presented in the graphic.NOTE: Each correct selection is worth one point.
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #62
HOTSPOT (Drag and Drop is not supported)You have a Microsoft 365 subscription that uses Microsoft Intune and contains the users shown in the following table.Group2 has been assigned in the Enrollment Status Page.You have the devices shown in the following table.You capture and upload the hardware IDs of the devices in the marketing department.You configure Windows Autopilot.For each of the following statements, select Yes if the statement is true. Otherwise, select No.NOTE: Each correct selection is worth o
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #63
You use the Microsoft Deployment Toolkit (MDT) to manage Windows 11 deployments.From Deployment Workbench, you modify the WinPE settings and add PowerShell support.You need to generate a new set of WinPE boot image files that contain the updated settings.What should you do?
A. From the Deployment Shares node, update the deployment share
B. From the Advanced Configuration node, create new media
C. From the Packages node, import a new operating system package
D. From the Operating Systems node, import a new operating system
View answer
Correct Answer: A
Question #64
DRAG DROP (Drag and Drop is not supported)You have a Microsoft 365 subscription that includes Microsoft Intune.You need to implement a Microsoft Defender for Endpoint solution that meets the following requirements:-Enforces compliance for Defender for Endpoint by using Conditional Access -Prevents suspicious scripts from running on devicesWhat should you configure? To answer, drag the appropriate features to the correct requirements. Each feature may be used once, more than once, or not at all. You may need
A. dministrative Templates
B. ndpoint protection
C. evice restrictions
D. ustom
View answer
Correct Answer: A
Question #65
You have a Microsoft 365 E5 subscription and 100 computers that run Windows 10.You need to deploy Microsoft Office Professional Plus 2019 to the computers by using Microsoft Office Deployment Tool (ODT).What should you use to create a customization file for ODT?
A. he Microsoft 365 admin center
B. he Microsoft Intune admin center
C. he Microsoft Purview compliance portal
D. he Microsoft 365 Apps admin center
View answer
Correct Answer: D
Question #66
You have a Microsoft 365 E5 subscription. The subscription contains 25 computers that run Windows 11 and are enrolled in Microsoft Intune. You need to onboard the devices to Microsoft Defender for Endpoint. What should you create in the Microsoft Intune admin center?
A. ee Explanation section for answer
View answer
Correct Answer: C
Question #67
You have two computers named Computer1 and Computer2 that run Windows 10. Computer2 has Remote Desktop enabled.From Computer1, you connect to Computer2 by using Remote Desktop Connection.You need to ensure that you can access the local drives on Computer1 from within the Remote Desktop session.What should you do?
A. rom Computer2, configure the Remote Desktop settings
B. rom Windows Defender Firewall on Computer1, allow Remote Desktop
C. rom Windows Defender Firewall on Computer2, allow File and Printer Sharing
D. rom Computer1, configure the Remote Desktop Connection settings
View answer
Correct Answer: D
Question #68
Your network contains an on-premises Active Directory domain. The domain contains two computers named Computer1 and Computer? that run Windows 10.You install Windows Admin Center on Computer1.You need to manage Computer2 from Computer1 by using Windows Admin Center.What should you do on Computed?
A. pdate the TrustedHosts list
B. un the Enable-PSRemoting cmdlet
C. llow Windows Remote Management (WinRM) through the Microsoft Defender firewall
D. dd an inbound Microsoft Defender Firewall rule
View answer
Correct Answer: B
Question #69
You have a Microsoft 365 E5 subscription and 25 Apple iPads.You need to enroll the iPads in Microsoft Intune by using the Apple Configurator enrollment method. What should you do first?
A. onfigure an Apply MDM push certificate
B. dd your user account as a device enrollment manager (DEM)
C. odify the enrollment restrictions
D. pload a file that has the device identifiers for each iPad
View answer
Correct Answer: A
Question #70
You have an Azure AD group named Group1. Group! contains two Windows 10 Enterprise devices named Device1 and Device2. You create a device configuration profile named Profile1. You assign Profile! to Group1. You need to ensure that Profile! applies to Device1 only. What should you modify in Profile 1?
A. ee Explanation section for answer
View answer
Correct Answer: A
Question #71
You have a Microsoft 365 subscription that contains a user named User1. User1 is assigned a Windows 10/11 Enterprise E3 license.You use Microsoft Intune Suite to manage devices.User1 activates the following devices:-Device1: Windows 11 Enterprise-Device2: Windows 10 Enterprise-Device3: Windows 11 EnterpriseHow many more devices can User1 activate?
A.
B.
C.
D.
View answer
Correct Answer: A
Question #72
You have computers that run Windows 10 and are managed by using Microsoft Intune.Users store their files in a folder named D:\Folder1.You need to ensure that only a trusted list of applications is granted write access to D:\Folder1.What should you configure in the device configuration profile?
A. icrosoft Defender Exploit Guard
B. icrosoft Defender Application Guard
C. icrosoft Defender SmartScreen
D. icrosoft Defender Application Control
View answer
Correct Answer: A
Question #73
You have a Microsoft 365 E5 subscription and 100 unmanaged iPad devices.You need to deploy a specific iOS update to the devices. Users must be prevented from manually installing a more recent version of iOS.Which two actions should you perform? Each correct answer presents part of the solution.NOTE: Each correct selection is worth one point.
A. hen a user approves the uninstall
B. s soon as the policy is received
C. ext Tuesday
D. he first Tuesday of the next month
View answer
Correct Answer: AB
Question #74
You have a Microsoft 365 subscription that uses Microsoft Intune Suite.You use Microsoft Intune to manage devices.Auto-enrollment in Intune is configured.You have 100 Windows 11 devices in a workgroup.You need to connect the devices to the corporate wireless network and enroll 100 new Windows 11 devices in Intune.What should you use?
A. provisioning package
B. Group Policy Object (GPO)
C. obile device management (MDM) automatic enrollment
D. device configuration policy
View answer
Correct Answer: A

View The Updated Microsoft Exam Questions

SPOTO Provides 100% Real Microsoft Exam Questions for You to Pass Your Microsoft Exam!

View Answers after Submission

Please submit your email and WhatsApp to get the answers of questions.

Note: Please make sure your email ID and Whatsapp are valid so that you can get the correct exam results.

Email:
Whatsapp/phone number: